06-30-2017 12:57 AM - edited 03-01-2019 05:16 AM
Hi,
I'm currently running the 2.1(1h) in production with 9936 Spine / 93xxx-EX.
For a specific tenant, my customer wants to filter traffic between each vlan through an external firewall as you can see attached.
I would like to find the easiest way to do that in ACI.
Notes :
- Firewall is a physical cluster
- No device package available
- Satic routing between ACI and the Firewall (L3 out)
- Vlan/EPg gw in ACI
Do you have any advices about this kind of design (Unmanaged mode, Pbr...) ?
Regards,
Ju
Solved! Go to Solution.
06-30-2017 08:51 AM
Ju,
It is unlikely that you will be provided a design recommendation from the support forum community. The Cisco Advanced Services team would be able to able to provide that service.
In regards to L4-L7, it best to read through the Service Graph Design White Paper (below). The paper covers designs for firewalls in Go-To (routed) and Go-Through (Bridged) mode along with bridge domain and VRF best practices.
For managed vs unmanaged, it depends on if you want to only force traffic to the firewall as opposed to ACI deploying all configuration onto the device. If no device package is available for your firewall, then your only option would be to try unmanaged mode.
If you want to look into PBR, then I would suggest the guide below.
Jason
06-30-2017 08:51 AM
Ju,
It is unlikely that you will be provided a design recommendation from the support forum community. The Cisco Advanced Services team would be able to able to provide that service.
In regards to L4-L7, it best to read through the Service Graph Design White Paper (below). The paper covers designs for firewalls in Go-To (routed) and Go-Through (Bridged) mode along with bridge domain and VRF best practices.
For managed vs unmanaged, it depends on if you want to only force traffic to the firewall as opposed to ACI deploying all configuration onto the device. If no device package is available for your firewall, then your only option would be to try unmanaged mode.
If you want to look into PBR, then I would suggest the guide below.
Jason
06-30-2017 09:51 PM
Thank you Jason for your reply.
I will discuss about this topic with my Cisco representative.
Regards
Ju
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide